|
|
|
|
|
by tialaramex
2491 days ago
|
|
Er, sure? If you think the lesson here is "SSL/TLS is terrible, look at the bad implementations people have done" then you screwed up. What's notable is that TLS is good enough that this even matters. Compare the situation with PGP and S/MIME. Instead of a list of bad examples, as a contrast to how it should be done, all you can say for those entire ecosystems is "Well, this is terrible, never do any of this". The same story applies for the Web PKI. There have been a bunch of problems with the Web PKI over the years. But rather than "This PKI is terrible" the lesson is actually "This PKI is so good that it actually matters if things go wrong". |
|